sudo 1.6.x and 1.7.x before 1.7.9p1, and 1.8.x before 1.8.4p5, does not properly support configurations that use a netmask syntax, which allows local users to bypass intended command restrictions in opportunistic circumstances by executing a command on a host that has an IPv4 address.
2012-05-18T18:55:01.813
2025-04-11T00:51:21.963
Deferred
CVSSv2: 7.2 (HIGH)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | todd_miller | sudo | 1.6 | Yes |
Application | todd_miller | sudo | 1.6.1 | Yes |
Application | todd_miller | sudo | 1.6.2 | Yes |
Application | todd_miller | sudo | 1.6.2p3 | Yes |
Application | todd_miller | sudo | 1.6.3 | Yes |
Application | todd_miller | sudo | 1.6.3_p7 | Yes |
Application | todd_miller | sudo | 1.6.4 | Yes |
Application | todd_miller | sudo | 1.6.4p2 | Yes |
Application | todd_miller | sudo | 1.6.5 | Yes |
Application | todd_miller | sudo | 1.6.6 | Yes |
Application | todd_miller | sudo | 1.6.7 | Yes |
Application | todd_miller | sudo | 1.6.7p5 | Yes |
Application | todd_miller | sudo | 1.6.8 | Yes |
Application | todd_miller | sudo | 1.6.8p12 | Yes |
Application | todd_miller | sudo | 1.6.9 | Yes |
Application | todd_miller | sudo | 1.6.9p20 | Yes |
Application | todd_miller | sudo | 1.6.9p21 | Yes |
Application | todd_miller | sudo | 1.6.9p22 | Yes |
Application | todd_miller | sudo | 1.6.9p23 | Yes |